This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2011-09-15
Product Sharepoint Workspace Last view 2011-09-15
Version 2010 Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:microsoft:sharepoint_workspace:2010:*:x64:*:*:*:*:* 1
cpe:2.3:a:microsoft:sharepoint_workspace:2010:sp1:x32:*:*:*:*:* 1
cpe:2.3:a:microsoft:sharepoint_workspace:2010:*:x32:*:*:*:*:* 1
cpe:2.3:a:microsoft:sharepoint_workspace:2010:sp1:x64:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4 2011-09-15 CVE-2011-1892

Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-200 Information Exposure

Oval Markup Language : Definitions

OvalID Name
oval:org.mitre.oval:def:12907 SharePoint Remote File Disclosure Vulnerability

Open Source Vulnerability Database (OSVDB)

id Description
75392 Microsoft SharePoint XML File Arbitrary File Disclosure
75381 Microsoft SharePoint XML / XSL File Handling Unspecified Arbitrary File Discl...

ExploitDB Exploits

id Description
17873 File disclosure via XEE in SharePoint 2007/2010 and DotNetNuke < 6

OpenVAS Exploits

id Description
2011-09-14 Name : Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858)
File : nvt/secpod_ms11-074.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2011-B-0115 Multiple Vulnerabilities in Microsoft Office SharePoint
Severity: Category II - VMSKEY: V0030239

Snort® IPS/IDS

Date Description
2014-01-10 Microsoft Office SharePoint XML external entity exploit attempt
RuleID : 20115 - Type : SERVER-WEBAPP - Revision : 10

Nessus® Vulnerability Scanner

id Description
2011-09-14 Name: The remote host is affected by multiple privilege escalation and information ...
File: smb_nt_ms11-074.nasl - Type: ACT_GATHER_INFO